Solutions
Cybersecurity & Secure Access
SOT fortifies IT environments against evolving digital threats. Implementing Next-Generation Firewalls (NGFW), robust endpoint protection, and secure VPNs, SOT guarantees data integrity and network defense for corporate infrastructure.
Security work divides into two questions: what is exposed, and what would be noticed. Most organisations have invested in the first — a firewall, antivirus, perhaps multi-factor authentication — and very little in the second, which is why intrusions are typically discovered long after they began and usually by their consequences.
The most effective single measure available to a building full of connected equipment is segmentation, and it is the one most often left undone. Cameras, door controllers, building management and corporate workstations frequently share one flat network, so a single compromised device with a default password can reach everything. Separating them is a switching and policy exercise rather than a product purchase, which is part of why it gets skipped.
SOT approaches this as infrastructure. The perimeter, the segmentation, the endpoints, the identity layer and the monitoring are designed as one posture rather than assembled from whichever products were bought in which year, and the National Cybersecurity Authority's Essential Cybersecurity Controls give a defensible framework to measure it against.
What this covers
Next-generation firewalls
Perimeter and internal firewalls with application awareness, intrusion prevention and TLS inspection, sized for real throughput with inspection enabled rather than for the datasheet figure with it off.
Network segmentation
Surveillance, building systems, guest and corporate traffic separated with policy between them — the highest-value control most sites have never implemented.
Endpoint protection
Detection and response on workstations and servers, with the visibility to say what a device did rather than only that something was blocked.
Identity and access
Multi-factor authentication, privileged access control and joiner-mover-leaver process, because most incidents begin with a valid credential rather than an exploit.
Email and web filtering
Filtering at the two channels users actually get attacked through, including attachment and link analysis rather than reputation alone.
Monitoring and logging
Centralised logs with retention and alerting, so an investigation has evidence to work from instead of devices that overwrote their logs a week ago.
Backup and recovery
Backups that are tested, versioned and out of reach of the systems they protect — the only control that reliably answers ransomware.
Vulnerability management
Regular scanning and a patching cadence, so exposure is a tracked number rather than something discovered during an incident.
Explore in detail
Each of these has a page of its own — what it involves, what it covers, and the questions that decide the specification.
How we deliver it
- 01
Site survey
An engineer walks the site and records what is actually there — cable routes, containment, power, ceiling voids, existing equipment and its condition. Most of the cost overruns on a project of this kind are either discovered here or discovered late.
- 02
Design and Bill of Quantities
A drawn design and an itemised BoQ: every part, its quantity and its price, with the reasoning for the specification written beside it. You own the document whether or not you buy from us.
- 03
Supply from Riyadh stock
Equipment released against the BoQ from local stock where we hold it, or ordered directly from the vendor where we do not. Serial numbers are recorded against your project, so a warranty claim later does not depend on you having kept the paperwork.
- 04
Installation and commissioning
Our own engineers install, terminate, configure and test. The testing is documented — link certification, camera fields of view, failover checks — and the results are handed over as part of the file rather than described verbally.
- 05
Handover and support
As-built drawings, configuration backups, credentials and test results, plus training for whoever will run it day to day. Support and warranty are handled by the same team that installed it.
Standards and regulations
What a deployment is measured against. A consultant or a main contractor will check a proposal against these, so they are named rather than implied.
- NCA Essential Cybersecurity Controls
- The Saudi National Cybersecurity Authority's ECC is the baseline framework for organisations in the Kingdom, and it is what an assessment is most likely to be measured against.
- ISO/IEC 27001
- Information security management systems. Useful as a structure even where certification is not the goal, because it forces ownership and review rather than one-off implementation.
- IEC 62443
- Security for industrial automation and control systems — the relevant framework wherever operational technology and building systems share infrastructure with IT.
- PDPL
- Saudi Arabia's Personal Data Protection Law bears directly on surveillance footage, biometric enrolment and access logs, all of which are personal data.
- CIS Controls
- A prioritised, practical control set. Its value is the ordering: it says which handful of measures to do first, which is exactly what a stretched team needs.
Sectors we deploy this in
Questions we get asked
Can SOT help align our network security with NCA requirements?
SOT configures NGFW and endpoint deployments with NCA-aligned controls in mind for regulated-sector clients.
What's included in a secure VPN deployment?
SOT's VPN deployments cover remote-access and site-to-site connectivity secured through the same NGFW platforms.
Does SOT provide ongoing monitoring or just installation?
SOT installs and configures the security stack; ongoing monitoring/support terms are confirmed during scoping.
